Skip to main content

CertManagerCertificatePolicy

Resource CertManagerCertificatePolicy in pulumi-infisical.
9 min read

Resource CertManagerCertificatePolicy in pulumi-infisical.

Pulumi type: infisical:index/certManagerCertificatePolicy:CertManagerCertificatePolicy.

name is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

Example#

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

Arguments#

PropertyTypeRequiredDescription
algorithmsCertManagerCertificatePolicyAlgorithms (input)noAlgorithm constraints for the certificate policy. Omit the block to accept any algorithm; each list restricts its own kind independently and needs at least one value when set.
basicConstraintsCertManagerCertificatePolicyBasicConstraints (input)noBasic constraints policy for the certificate policy, controlling whether issued certificates may act as certificate authorities.
descriptionstringnoThe description of the certificate policy (max 255 characters). Omit the attribute instead of passing an empty string.
extendedKeyUsagesCertManagerCertificatePolicyExtendedKeyUsages (input)noExtended key usage policies for the certificate policy. When this block is present, requested extended key usages must be within the union of allowed and required; setting allowed and required to empty lists denies all extended key usages. Omit the block for no constraint.
keyUsagesCertManagerCertificatePolicyKeyUsages (input)noKey usage policies for the certificate policy. When this block is present, requested key usages must be within the union of allowed and required; setting allowed and required to empty lists denies all key usages. Omit the block for no constraint.
namestringnoThe name of the certificate policy. Must be in slug format: lowercase letters and numbers, separated by single hyphens (e.g. 'web-server-policy').
sansCertManagerCertificatePolicySan (input)[]noSubject alternative name (SAN) policies for the certificate policy
subjectsCertManagerCertificatePolicySubject (input)[]noSubject attribute policies for the certificate policy. Each block constrains a single subject DN attribute (e.g. common_name, organization). Values are matched against the corresponding attribute parsed from the CSR; the '*' wildcard matches any sequence of characters (including dots).commonName matches the CN attribute only.domainComponent(DC) is an independent attribute matched separately from common_name: a certificate may carry multiple DC values, and each is matched individually against this block.
validityCertManagerCertificatePolicyValidity (input)noValidity constraints for the certificate policy

Outputs#

Computed outputs are produced by the provider. They are not constructor arguments.

PropertyTypeComputedDescription
algorithmsCertManagerCertificatePolicyAlgorithms (output)noAlgorithm constraints for the certificate policy. Omit the block to accept any algorithm; each list restricts its own kind independently and needs at least one value when set.
basicConstraintsCertManagerCertificatePolicyBasicConstraints (output)noBasic constraints policy for the certificate policy, controlling whether issued certificates may act as certificate authorities.
descriptionstringnoThe description of the certificate policy (max 255 characters). Omit the attribute instead of passing an empty string.
extendedKeyUsagesCertManagerCertificatePolicyExtendedKeyUsages (output)noExtended key usage policies for the certificate policy. When this block is present, requested extended key usages must be within the union of allowed and required; setting allowed and required to empty lists denies all extended key usages. Omit the block for no constraint.
keyUsagesCertManagerCertificatePolicyKeyUsages (output)noKey usage policies for the certificate policy. When this block is present, requested key usages must be within the union of allowed and required; setting allowed and required to empty lists denies all key usages. Omit the block for no constraint.
namestringnoThe name of the certificate policy. Must be in slug format: lowercase letters and numbers, separated by single hyphens (e.g. 'web-server-policy').
sansCertManagerCertificatePolicySan (output)[]noSubject alternative name (SAN) policies for the certificate policy
subjectsCertManagerCertificatePolicySubject (output)[]noSubject attribute policies for the certificate policy. Each block constrains a single subject DN attribute (e.g. common_name, organization). Values are matched against the corresponding attribute parsed from the CSR; the '*' wildcard matches any sequence of characters (including dots).commonName matches the CN attribute only.domainComponent(DC) is an independent attribute matched separately from common_name: a certificate may carry multiple DC values, and each is matched individually against this block.
validityCertManagerCertificatePolicyValidity (output)noValidity constraints for the certificate policy

CertManagerCertificatePolicyAlgorithms (input)#

Input object CertManagerCertificatePolicyAlgorithms. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
keyAlgorithmsstring[]noList of allowed key algorithms (at least one value when set). Supported values: RSA-2048, RSA-3072, RSA-4096, ECDSA-P256, ECDSA-P521, ECDSA-P384
signaturesstring[]noList of allowed signature algorithms (at least one value when set). Supported values: SHA256-RSA, SHA512-RSA, SHA384-ECDSA, SHA384-RSA, SHA256-ECDSA, SHA512-ECDSA

CertManagerCertificatePolicyBasicConstraints (input)#

Input object CertManagerCertificatePolicyBasicConstraints. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
isCastringnoPolicy for the CA flag (basic constraints CA:TRUE) on issued certificates. Possible values: allowed, required, denied
maxPathLengthnumbernoMaximum path length constraint for CA certificates. Use -1 for unlimited, or a non-negative integer to cap how many intermediate CAs may appear below a certificate issued under this policy. Only applies when isCa is allowed or required; it is ignored when isCa is denied.

CertManagerCertificatePolicyExtendedKeyUsages (input)#

Input object CertManagerCertificatePolicyExtendedKeyUsages. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
allowedsstring[]noList of allowed extended key usages. Possible values: client_auth, server_auth, code_signing, email_protection, ocsp_signing, time_stamping
deniedsstring[]noList of denied extended key usages. Possible values: client_auth, server_auth, code_signing, email_protection, ocsp_signing, time_stamping
requiredsstring[]noList of required extended key usages. Possible values: client_auth, server_auth, code_signing, email_protection, ocsp_signing, time_stamping

CertManagerCertificatePolicyKeyUsages (input)#

Input object CertManagerCertificatePolicyKeyUsages. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
allowedsstring[]noList of allowed key usages. Possible values: digital_signature, key_encipherment, non_repudiation, data_encipherment, key_agreement, key_cert_sign, crl_sign, encipher_only, decipher_only
deniedsstring[]noList of denied key usages. Possible values: digital_signature, key_encipherment, non_repudiation, data_encipherment, key_agreement, key_cert_sign, crl_sign, encipher_only, decipher_only
requiredsstring[]noList of required key usages. Possible values: digital_signature, key_encipherment, non_repudiation, data_encipherment, key_agreement, key_cert_sign, crl_sign, encipher_only, decipher_only

CertManagerCertificatePolicySan (input)#

Input object CertManagerCertificatePolicySan. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
allowedsstring[]noList of allowed values for this SAN type
deniedsstring[]noList of denied values for this SAN type
requiredsstring[]noList of required values for this SAN type
typestringyesThe SAN type. Possible values: dns_name, ip_address, email, uri

CertManagerCertificatePolicySubject (input)#

Input object CertManagerCertificatePolicySubject. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
allowedsstring[]noList of allowed values for this subject attribute. Supports the '*' wildcard.
deniedsstring[]noList of denied values for this subject attribute. Supports the '*' wildcard.
requiredsstring[]noList of required values for this subject attribute. Supports the '*' wildcard.
typestringyesThe subject attribute type. Possible values: common_name, organization, organizational_unit, country, state, locality, domain_component

CertManagerCertificatePolicyValidity (input)#

Input object CertManagerCertificatePolicyValidity. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
maxstringnoMaximum validity period (e.g., '90d', '2y', '6m')

CertManagerCertificatePolicyAlgorithms (output)#

Output object CertManagerCertificatePolicyAlgorithms. Fields below belong to this object.

PropertyTypeAlways presentDescription
keyAlgorithmsstring[]noList of allowed key algorithms (at least one value when set). Supported values: RSA-2048, RSA-3072, RSA-4096, ECDSA-P256, ECDSA-P521, ECDSA-P384
signaturesstring[]noList of allowed signature algorithms (at least one value when set). Supported values: SHA256-RSA, SHA512-RSA, SHA384-ECDSA, SHA384-RSA, SHA256-ECDSA, SHA512-ECDSA

CertManagerCertificatePolicyBasicConstraints (output)#

Output object CertManagerCertificatePolicyBasicConstraints. Fields below belong to this object.

PropertyTypeAlways presentDescription
isCastringnoPolicy for the CA flag (basic constraints CA:TRUE) on issued certificates. Possible values: allowed, required, denied
maxPathLengthnumbernoMaximum path length constraint for CA certificates. Use -1 for unlimited, or a non-negative integer to cap how many intermediate CAs may appear below a certificate issued under this policy. Only applies when isCa is allowed or required; it is ignored when isCa is denied.

CertManagerCertificatePolicyExtendedKeyUsages (output)#

Output object CertManagerCertificatePolicyExtendedKeyUsages. Fields below belong to this object.

PropertyTypeAlways presentDescription
allowedsstring[]noList of allowed extended key usages. Possible values: client_auth, server_auth, code_signing, email_protection, ocsp_signing, time_stamping
deniedsstring[]noList of denied extended key usages. Possible values: client_auth, server_auth, code_signing, email_protection, ocsp_signing, time_stamping
requiredsstring[]noList of required extended key usages. Possible values: client_auth, server_auth, code_signing, email_protection, ocsp_signing, time_stamping

CertManagerCertificatePolicyKeyUsages (output)#

Output object CertManagerCertificatePolicyKeyUsages. Fields below belong to this object.

PropertyTypeAlways presentDescription
allowedsstring[]noList of allowed key usages. Possible values: digital_signature, key_encipherment, non_repudiation, data_encipherment, key_agreement, key_cert_sign, crl_sign, encipher_only, decipher_only
deniedsstring[]noList of denied key usages. Possible values: digital_signature, key_encipherment, non_repudiation, data_encipherment, key_agreement, key_cert_sign, crl_sign, encipher_only, decipher_only
requiredsstring[]noList of required key usages. Possible values: digital_signature, key_encipherment, non_repudiation, data_encipherment, key_agreement, key_cert_sign, crl_sign, encipher_only, decipher_only

CertManagerCertificatePolicySan (output)#

Output object CertManagerCertificatePolicySan. Fields below belong to this object.

PropertyTypeAlways presentDescription
allowedsstring[]noList of allowed values for this SAN type
deniedsstring[]noList of denied values for this SAN type
requiredsstring[]noList of required values for this SAN type
typestringyesThe SAN type. Possible values: dns_name, ip_address, email, uri

CertManagerCertificatePolicySubject (output)#

Output object CertManagerCertificatePolicySubject. Fields below belong to this object.

PropertyTypeAlways presentDescription
allowedsstring[]noList of allowed values for this subject attribute. Supports the '*' wildcard.
deniedsstring[]noList of denied values for this subject attribute. Supports the '*' wildcard.
requiredsstring[]noList of required values for this subject attribute. Supports the '*' wildcard.
typestringyesThe subject attribute type. Possible values: common_name, organization, organizational_unit, country, state, locality, domain_component

CertManagerCertificatePolicyValidity (output)#

Output object CertManagerCertificatePolicyValidity. Fields below belong to this object.

PropertyTypeAlways presentDescription
maxstringnoMaximum validity period (e.g., '90d', '2y', '6m')